Skip to content

Infrastructure Modules Reference ​

Mantle ships 13 OpenTofu modules. From 2.1.0 they are part of the published @j0nathan-ll0yd/cli package, so an instance sources them out of its own node_modules — the version is pinned by the instance's lockfile and moves only as a reviewed dependency bump:

hcl
module "core" { source = "../node_modules/@j0nathan-ll0yd/cli/modules/core" }

mantle generate infra writes this path for you; you should not need to type it. Before 2.1.0 the only reachable copy was a sibling ../mantle checkout on disk, which meant a deploy applied whatever branch that working tree happened to be on. resolveModulesPath still falls back to a sibling checkout for instances pinned to an older CLI, and --modules-path still overrides everything.

Every module accepts name_prefix and tags from module.core.


core ​

Foundation module. Produces the naming prefix, common tags, and IAM assume-role policies consumed by every other module.

InputTypeRequiredDescription
project_namestringyesLowercase alphanumeric with hyphens
environmentstringyesdev, staging, or prod
extra_tagsmap(string)noAdditional tags merged into common set
OutputDescription
name_prefixEnvironment-aware prefix (e.g. staging)
common_tagsTag map for all resources
account_idAWS account ID
regionAWS region
lambda_assume_role_policyIAM JSON for Lambda assume role
lambda_gateway_assume_role_policyIAM JSON for Lambda + API Gateway assume role
lambda_edge_assume_role_policyIAM JSON for Lambda@Edge assume role
lambda_xray_policy_arnARN of shared X-Ray IAM policy

Usage: aws-cloudformation-media-downloader/infra/main.tf


api-gateway ​

REST API Gateway with deployment, stage, optional custom authorizer, usage plan with API key, CORS error responses, and CloudWatch logging.

InputTypeRequiredDescription
name_prefixstringyesFrom module.core
tagsmap(string)yesFrom module.core
descriptionstringnoAPI description (default: "Mantle API")
endpoint_typestringnoREGIONAL, EDGE, or PRIVATE
authorizer_lambda_invoke_arnstringnoInvoke ARN for custom authorizer
authorizer_ttl_secondsnumbernoAuthorizer cache TTL (default: 300)
create_usage_planboolnoCreate usage plan + API key (default: true)
throttle_burst_limitnumbernoMax concurrent requests (default: 50)
throttle_rate_limitnumbernoRequests/second (default: 100)
quota_limitnumbernoDaily request quota (default: 10000)
cors_allow_originstringnoCORS origin for error responses
xray_tracing_enabledboolnoEnable X-Ray (default: true)
redeployment_triggerstringnoHash to trigger redeployment
OutputDescription
rest_api_idREST API ID
rest_api_root_resource_idRoot resource ID for child resources
rest_api_execution_arnExecution ARN
invoke_urlBase invoke URL
api_key_valueAPI key (sensitive)
authorizer_idCustom authorizer ID
stage_nameDeployed stage name
api_nameAPI name (for CloudWatch dimensions)

Usage: aws-cloudformation-media-downloader/infra/main.tf


lambda ​

Single Lambda function with IAM role, CloudWatch log group, and trigger configuration. One .tf file per Lambda in the instance's infra/ directory.

InputTypeRequiredDescription
function_namestringyesShort name (prefixed with name_prefix)
name_prefixstringyesFrom module.core
source_dirstringyesPath to build output directory
assume_role_policystringyesIAM assume role JSON from module.core
regionstringyesAWS region
account_idstringyesAWS account ID
tagsmap(string)yesFrom module.core
environmentstringyesdev, staging, or prod
handlerstringnoEntrypoint (default: index.handler)
runtimestringnoRuntime (default: nodejs24.x)
architecturestringnoarm64 or x86_64 (default: arm64)
memory_sizenumbernoMemory in MB (default: 512)
timeoutnumbernoTimeout in seconds (default: 30)
environment_variablesmap(string)noFunction-specific env vars
layerslist(string)noLayer ARNs
additional_policy_arnslist(string)noExtra IAM policy ARNs
inline_policiesmap(string)noInline IAM policy JSON
api_gateway_enabledboolnoAPI Gateway trigger
sqs_trigger_arnstringnoSQS trigger ARN
schedule_expressionstringnoCloudWatch schedule
eventbridge_rule_arnslist(string)noEventBridge rule ARNs
is_edge_functionboolnoLambda@Edge mode (forces x86_64, enables publish)
package_typestringnoZip or Image
ephemeral_storagenumbernoEphemeral storage in MB (512-10240)
OutputDescription
function_nameFull function name
function_arnFunction ARN
invoke_arnInvoke ARN (for API Gateway)
role_nameIAM role name
role_arnIAM role ARN
log_group_nameCloudWatch log group name
qualified_arnVersion-qualified ARN (for Lambda@Edge)

Usage: aws-cloudformation-media-downloader/infra/lambda_health_sync.tf


database/aurora-dsql ​

Aurora DSQL cluster with IAM authentication policies for both per-Lambda roles (DbConnect) and migration admin (DbConnectAdmin).

InputTypeRequiredDescription
name_prefixstringyesFrom module.core
tagsmap(string)yesFrom module.core
deletion_protectionboolnoEnable deletion protection (default: true)
OutputDescription
cluster_arnDSQL cluster ARN
cluster_identifierCluster identifier
cluster_endpointCluster endpoint ({id}.dsql.{region}.on.aws)
connect_policy_arnIAM policy ARN for DbConnect (per-Lambda)
admin_connect_policy_arnIAM policy ARN for DbConnectAdmin (migrations)

Usage: mantle-LifegamesPortal/infra/main.tf


eventbridge ​

Custom EventBridge event bus. Rules and targets are generated per-Lambda by mantle generate infra.

InputTypeRequiredDescription
bus_namestringyesBus name suffix
name_prefixstringyesFrom module.core
tagsmap(string)yesFrom module.core
OutputDescription
bus_nameFull EventBridge bus name
bus_arnEventBridge bus ARN

Usage: mantle-LifegamesPortal/infra/eventbridge.tf


storage ​

S3 bucket with optional CloudFront distribution, CORS, transfer acceleration, intelligent tiering, and event notifications.

InputTypeRequiredDescription
bucket_namestringyesShort bucket name
name_prefixstringyesFrom module.core
tagsmap(string)yesFrom module.core
project_namestringnoFor globally-unique naming
cloudfront_enabledboolnoCreate CloudFront distribution
transfer_acceleration_enabledboolnoS3 transfer acceleration
intelligent_tiering_enabledboolnoAuto storage class optimization
cors_allowed_originslist(string)noCORS origins
versioning_enabledboolnoS3 versioning
eventbridge_notifications_enabledboolnoS3 events to EventBridge
lambda_notificationslist(object)noDirect Lambda notification targets
OutputDescription
bucket_idS3 bucket ID
bucket_arnS3 bucket ARN
bucket_regional_domain_nameRegional domain name
cloudfront_domain_nameCloudFront domain (if enabled)
cloudfront_distribution_idCloudFront ID (if enabled)
cloudfront_distribution_arnCloudFront ARN (if enabled)

Usage: mantle-LifegamesPortal/infra/storage.tf


queue ​

SQS queue with dead-letter queue, long polling, and optional DLQ alarm.

InputTypeRequiredDescription
queue_namestringyesShort queue name
name_prefixstringyesFrom module.core
tagsmap(string)yesFrom module.core
visibility_timeout_secondsnumbernoShould be >= 6x consumer Lambda timeout (default: 180)
max_receive_countnumbernoAttempts before DLQ (default: 3)
receive_wait_time_secondsnumbernoLong polling wait (default: 20)
retention_secondsnumbernoMessage retention (default: 4 days)
dlq_retention_secondsnumbernoDLQ retention (default: 14 days)
enable_dlq_alarmboolnoDLQ CloudWatch alarm (default: true)
alarm_sns_topic_arnslist(string)noSNS topics for alarm notifications
OutputDescription
queue_urlMain queue URL
queue_arnMain queue ARN
queue_nameMain queue name
dlq_urlDead letter queue URL
dlq_arnDead letter queue ARN
dlq_nameDead letter queue name

Usage: aws-cloudformation-media-downloader/infra/queue.tf


sns ​

SNS topic with optional mobile push platform application (APNS/GCM).

InputTypeRequiredDescription
topic_namestringyesShort topic name
name_prefixstringyesFrom module.core
tagsmap(string)noFrom module.core
platformstringnoAPNS, APNS_SANDBOX, GCM, or null
platform_credentialstringnoPrivate key (APNS) or API key (GCM)
platform_principalstringnoSSL certificate (APNS only)
OutputDescription
topic_arnSNS topic ARN
topic_nameSNS topic name
platform_application_arnPlatform app ARN (empty if no platform)

Usage: aws-cloudformation-media-downloader/infra/sns.tf


dynamodb ​

DynamoDB table with optional GSIs, TTL, and point-in-time recovery.

InputTypeRequiredDescription
table_namestringyesShort table name
name_prefixstringyesFrom module.core
hash_keystringyesPartition key attribute name
attributeslist(object)yesAttribute definitions (name, type)
tagsmap(string)yesFrom module.core
range_keystringnoSort key attribute name
billing_modestringnoPAY_PER_REQUEST or PROVISIONED
ttl_attributestringnoTTL attribute name
global_secondary_indexeslist(object)noGSI definitions
point_in_time_recoveryboolnoEnable PITR
table_name_overridestringnoFull name override (bypasses prefix)
OutputDescription
table_nameDynamoDB table name
table_arnDynamoDB table ARN
table_idDynamoDB table ID

Usage: aws-cloudformation-media-downloader/infra/dynamodb.tf


idempotency ​

DynamoDB table pre-configured for Lambda Powertools idempotency (partition key id, TTL on expiration).

InputTypeRequiredDescription
name_prefixstringyesFrom module.core
tagsmap(string)yesFrom module.core
OutputDescription
table_nameIdempotency table name
table_arnIdempotency table ARN

observability ​

CloudWatch dashboard, Lambda/API/SQS/EventBridge alarms, and SNS alert topic.

InputTypeRequiredDescription
name_prefixstringyesFrom module.core
tagsmap(string)yesFrom module.core
enable_dashboardboolnoCreate dashboard (default: false, costs $3/month)
enable_alarmsboolnoCreate alarms (default: true)
lambda_function_nameslist(string)noLambda functions to monitor
lambda_error_thresholdnumbernoError count before alarm (default: 5)
api_gateway_namestringnoAPI name for monitoring
api_5xx_thresholdnumberno5xx count before alarm (default: 1)
sqs_dlq_nameslist(string)noDLQ names to alarm on
eventbridge_rule_nameslist(string)noEventBridge rules to alarm on
custom_alarmslist(object)noCustom metric alarms
OutputDescription
sns_topic_arnAlert SNS topic ARN (empty if alarms disabled)
dashboard_urlCloudWatch dashboard URL (empty if disabled)

websocket-api ​

WebSocket API Gateway with stage, route selection, and throttling.

InputTypeRequiredDescription
name_prefixstringyesFrom module.core
tagsmap(string)yesFrom module.core
route_selection_expressionstringnoRoute selection (default: $request.body.action)
stage_namestringnoStage name (default: live)
throttling_burst_limitnumbernoBurst limit (default: 100)
throttling_rate_limitnumbernoRate limit (default: 50)
OutputDescription
api_idWebSocket API ID
api_endpointWebSocket endpoint URL
execution_arnExecution ARN (for Lambda permissions)
stage_nameStage name
invoke_urlFull WebSocket URL (wss://.../{stage})

cloudfront-api ​

CloudFront distribution fronting an API Gateway origin, with optional Lambda@Edge associations and security headers.

InputTypeRequiredDescription
origin_domainstringyesAPI Gateway domain
name_prefixstringyesFrom module.core
tagsmap(string)noFrom module.core
origin_pathstringnoOrigin path prefix (e.g. /prod)
forwarded_headerslist(string)noHeaders to forward (default: Authorization, X-Api-Key)
lambda_edge_associationslist(object)noLambda@Edge associations
enable_security_headersboolnoAttach security headers policy (default: true)
price_classstringnoPrice class (default: PriceClass_100)
geo_restriction_typestringnonone, whitelist, or blacklist
OutputDescription
distribution_domain_nameCloudFront domain name
distribution_idDistribution ID
distribution_arnDistribution ARN

Usage: aws-cloudformation-media-downloader/infra/cloudfront.tf